- Validated the openai-codex credential origin against the registry storage that supplies the bearer, closing the OAuth-leak path when authStorage and modelRegistry diverge.
- Added a regression test covering the mismatched storage case.
Fixes#6001
- Routed Codex web search through configured Responses base URLs, API keys, and headers while preserving the official OAuth backend.
- Refused OAuth leakage to custom endpoints and stopped explicitly selected providers from silently falling back.
- Added transport, safety, and fail-closed regression coverage.
Fixes#6001
TranscriptContainer gated committed-prefix compaction on version === undefined, so version-tracked AssistantMessageComponent history never compacted and every stream tick re-walked all N sealed blocks (depth-linear compose).
Compact fully-committed finalized blocks regardless of post-finalize version tracking: their rows are immutable native scrollback the terminal owns. A post-commit mutation no longer recommits on ordinary frames (no duplication) and rehydrates on the next destructive full replay (no loss). Adds the permanent bench/transcript-compose.bench.ts fixture; ratio(N5000/N500) drops 2.30 -> 0.90.
Fixes#5930
resolveBlobRefsInEntries handed every non-session entry to the recursive
async resolvePersistedBlobRefs walk, allocating and awaiting child promises
even for plain-text entries with no blob:sha256: refs. On large text-heavy
histories this dominated the blob_resolve phase of session open.
Add a cheap synchronous containsBlobRef precheck that early-exits on the
first ref and allocates nothing. Interleave the precheck with per-entry
initiation so positive entries still start resolution at the same relative
point as the old filter+map schedule (a later entry that gains a ref during
an earlier BlobStore.get is still scanned after that mutation).
Blob-free N=5000 fixture: blob_resolve median 19.5ms -> 1.1ms, zero
BlobStore.get calls.
Fixes#5922
- Probed Linux ffmpeg demuxers and fell back to ALSA when PulseAudio input is unavailable.
- Preserved recorder stderr so immediate capture failures report their real cause.
- Added regressions for ALSA selection and stderr diagnostics.
Fixes#5907
- 33d66643d removed the process-local URL response cache (#5803) but left
two fetch-kagi-toggle tests asserting the old reuse contract.
- Deleted the obsolete repeated-read reuse test (refetch behavior is
covered by fetch-raw-mode and search-url-paths regressions) and kept
the offset/limit selector contract without the no-network assertion.
Kept top-level custom tool descriptors when a retained xd device uses the same name. Added compact and inline inventory coverage for mounted-only and dual-presentation tools.
Subprocess.kill("SIGTERM") terminates a Windows child immediately
regardless of any handler, so the child in
"is idempotent even when close() had to escalate to SIGKILL" can never
trap SIGTERM to exercise the escalation path — the >=900ms grace-window
assertion would fail spuriously on win32 even though close() behaves
correctly there. Guards it the same way stdio.test.ts's
terminateStdioProcess describe block already skips its POSIX-only
real-signal tests.
- Fixed xd:// mount notices forcing their own model turn by deferring them until the next user prompt instead.
- Added `#pendingXdevMountDelta` field and `#takePendingXdevMountNotice()` to coalesce mount/unmount events and ride along with prompts.
- Mount and unmount events that cancel each other out before the next prompt are now dropped from the coalesced delta.
- Notices remain buffered during quiet startup mode (`startup.quiet`) and are delivered on the subsequent user prompt.
selectCollapsedTodos took the active-overflow branch at active.length >= cap, so exactly cap actives plus trailing pending returned the cap rows with an empty summary — the pending work vanished with no '… N more' indicator.
Use a strict '> cap' guard so equality falls through to the normal branch, which counts every hidden row.
Fixes#5873
The first pass anchored a slice on the active task, which still showed completed rows, kept the active item mid-window, and gave the two views divergent selection logic. Per reviewer, replace it with one shared policy both collapsed views run.
selectCollapsedTodos (todo.ts) omits completed/abandoned, pulls every active task (in_progress or subagent-matched pending) to the head in todo order, fills remaining rows with following pending tasks, and emits '… N more active todos' when active work alone exceeds the cap; it falls back to closed tasks for a settled phase so HUD persistence still renders. renderTreeList gains a trailingSummary primitive so item selection lives in the todo domain. The transient tool result reaches live subagent matches via setActiveTodoDescriptionsProvider, wired from interactive mode's observer registry, so both views share the active set.
Fixes#5873
Before: StdioTransport.close() did a bare `this.#process.kill()` — a single
direct SIGTERM to the immediate child, with no wait and no escalation. On
Linux (and other non-Windows/non-macOS POSIX hosts), the MCP server is
spawned detached (setsid, its own session leader) so terminal job-control
signals can't stop it. A detached server that traps/ignores SIGTERM — or a
grandchild it spawns inside that session — survived omp process exit and
was orphaned, re-parented to PID 1.
After: close() runs a bounded, idempotent teardown:
1. End stdin first (cooperative EOF) so a well-behaved server can exit on
its own before any signal is sent.
2. Send SIGTERM: to the whole process group (negative-pid `process.kill`)
when this transport actually spawned detached on a POSIX host, else to
the direct child only. A negative-pid signal is never attempted for a
non-detached transport, since it could hit an unrelated group. ESRCH
from the group signal means the group is already gone (treated as
success); any other group-signal failure falls back to a direct-child
signal.
3. Wait up to ~1s for the direct child to exit; if it hasn't, escalate to
SIGKILL (group-or-direct, same rule as step 2) and wait a further
bounded ~0.5s before returning. Total worst case (~1.5s) stays well
inside the ~3s MCP disconnect-all budget in agent-session.ts dispose().
`#process` is captured into a local and nulled before the first `await`, so
repeat/concurrent close() calls see it already cleared and skip re-signaling
— idempotent per the existing contract documented above close().
Extracted the signal/escalate logic into an exported `terminateStdioProcess`
(plus a `KillableSubprocess` structural type, decoupled from the stdio pipe
generics) so tests can drive group-signal escalation with an explicit
`detached` flag — `StdioTransport.connect()` ties `detached` to the host's
real `process.platform` via `resolveStdioSpawnCommand()`, so a POSIX
detached session can't be reproduced end-to-end through `connect()` on a
non-Linux dev/CI host, but a real detached process group can still be
spawned directly on any POSIX host to exercise it.
Tests added to stdio.test.ts: detached child trapping SIGTERM escalates to
SIGKILL; a detached parent's SIGTERM-trapping grandchild is only reached by
the group SIGKILL (proves group, not direct-child-only, signaling); a
well-behaved child closes promptly without escalating; a non-detached
transport never attempts a group signal. Extended
test/mcp-stdio-transport.test.ts's existing close() idempotency coverage
with a case where the first close() had to run the full escalation path.
Fixes#5578.
Create the resolved agent database parent before the synchronous compatibility store opens SQLite, and cover a fresh nested agent directory.
Fixes#5879
Both collapsed todo renderers took fixed edge slices: the tool result kept the tail eight (truncateFrom start) and the HUD kept the head five (base.slice), so a mid-phase in_progress task fell in the omitted middle of both.
Add an anchorIndex option to renderTreeList that slides the collapsed window over the anchored item with two-sided '… N more' summaries, and anchor both call sites on the in_progress task (HUD falls back to the first subagent-matched pending task).
Fixes#5873
Caller-provided output schemas are free-form JSON and cannot be represented by OpenAI strict tool schemas. Keep todo strict while explicitly sending task as non-strict.
- Preserved goal-mode tool injection for ordinary explicit tool lists.
- Kept plan-mode LSP and IRC unavailable under the host capability clamp.
- Added regressions for both capability boundaries.
- Added per-invocation task schemas with strict and permissive validation.
- Shared task and eval agent policy, artifacts, isolation, and lifecycle handling.
- Enabled host-restricted plan-mode eval agents and persisted their capability clamp.
Fixes#5279
Moved persisted roster discovery out of the Agent Hub UI so model-facing coordination can use the same disk-backed registration path.
Rehydrated parked peers before an empty hub list response and added a crash-resume regression test.
Fixes#5864
Only a 403 response that identifies unapproved_client now blocks generateAuthUrl before its clientless probe. Invalid metadata, invalid redirect, generic forbidden, retryable, and server failures preserve the probe path.
Consolidated fallback coverage across 400, 403, 429, and 503 responses.
Fixes#5852
Added #isDefinitiveRegistrationRejection so only non-retryable 4xx DCR errors block generateAuthUrl; 408/425/429 fall through to the clientless authorization probe alongside transport and 5xx failures.
Fixes#5852
Only a 4xx DCR client error blocks generateAuthUrl; transport (status 0) and 5xx failures fall through to the clientless authorization probe so providers accepting client-less authorization keep working.
Fixes#5852
Surfaced rejected dynamic client registration from generateAuthUrl before probing or returning an authorization URL without client_id.
Added coverage for a Cropwise-style 403 unapproved_client response.
Fixes#5852
Expanded `!` bash and `eval` execution output kept rendering the
`… N more lines (ctrl+o to expand)` footer after Ctrl+O revealed every
line, because `hiddenLineCount` was computed from the collapsed preview
window regardless of the `#expanded` (or sixel-passthrough) state.
Zero the hidden count whenever the full output is shown so
`buildStatusFooter()` stops advertising hidden lines and ctrl+o.
Fixes#5842